Skip to main content

Fortra Patches Critical Vulnerabilities in BoKS

0
Critical
Vulnerability
Published: 10/03/2026 (10/03/2026, 11:34:00 UTC)
Source: SecurityWeek

Description

Fortra has released patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical flaws. These vulnerabilities include an authentication bypass due to predictable password generation, a command injection vulnerability allowing root shell command execution, and a stack buffer overflow causing memory corruption. The issues affect BoKS deployments managing Active Directory service accounts and components accessible over the network. No exploitation in the wild has been reported. The vendor has issued patches addressing these vulnerabilities.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 11:46:14 UTC

Technical Analysis

Fortra patched eight vulnerabilities in BoKS, notably three critical ones: CVE-2026-79901 (CVSS 9.9) is an authentication bypass caused by predictable Active Directory service account passwords generated from a pseudo-random sequence seeded with the current Unix timestamp. An attacker knowing the service principal and approximate password-change time can reproduce and verify password candidates offline. CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the crlserver component exploitable via BCC and WSI REST or SOAP APIs, allowing authenticated users to execute shell commands as root. CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality enabling remote memory corruption. Additional high- and medium-severity issues include heap buffer overflows, out-of-bounds reads, insecure temporary file usage, and predictable password generation. No known active exploitation has been reported.

Potential Impact

Successful exploitation of these vulnerabilities could allow attackers to bypass authentication controls, execute arbitrary commands with root privileges, and cause memory corruption potentially leading to denial of service or code execution. The authentication bypass vulnerability could be exploited without administrative access if the attacker knows the service principal and timing information. The command injection vulnerability allows authenticated users to gain root shell access remotely. The memory corruption flaw could be triggered remotely, posing a risk of system compromise. These impacts are critical given BoKS's role in privileged access management.

Mitigation Recommendations

Fortra has released official patches addressing all identified vulnerabilities in BoKS. Organizations using BoKS should apply these patches promptly to remediate the critical authentication bypass, command injection, and memory corruption flaws. No mention of any vulnerabilities being exploited in the wild has been made, and the vendor recommends updating to the patched versions as the primary mitigation. No additional temporary workarounds or mitigations were specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.9,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/","fetched":true,"fetchedAt":"2026-10-03T11:46:09.596Z","wordCount":1021}

Threat ID: 6ac0eb01a43b0b3b89bd928f

Added to database: 10/03/2026, 11:46:09 UTC

Last enriched: 10/03/2026, 11:46:14 UTC

Last updated: 10/03/2026, 20:00:40 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses